OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-77193

HIGH · CVSS 7.5 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is susceptible to a Path Traversal vulnerability through the `id2wp_path` parameter, allowing unauthenticated attackers to access and read arbitrary files on the server. This could lead to the exposure of sensitive information, posing a significant risk to the integrity and confidentiality of the affected WordPress installations. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-77193
Severity
HIGH
CVSS
7.5
EPSS
0.36%
WordPress

Original NVD Description

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.